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IN THE CLAIMS 

1 . (Original) In a distributed network having a number of server computers and 
associated client devices, method of isolating infected client devices from uninfected client 
devices, comprising: 

correlating network related virus infection information; 

determining if a virus outbreak has occurred based on the correlated information; 
isolating infected client devices from uninfected client devices when the virus outbreak is 
confirmed; 

monitoring all data packets in the network for the virus; 
identifying a packet type associated with the virus; and 
blocking only the identified packet type. 

2. (Canceled) 

3. (Currently Amended) A method as recited in claim 2, further 
comprising: 

forwarding to a virus/worm virus analyzer unit coupled to the network 
computer viruo/worm virus sensor only those data packets deemed to be infected 
by the identified computer virus or computer worm a^e. 

4. (Currently Amended) A method as recited in claim 3, wherein in 

the first mode, copying by the traffic controller substantially all data packets 
included in the network traffic; and 
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forwarding the copied data packets to the virus/worm virus a nalyzer unit. 

5. (Currently Amended) A method as recited in claim 4, comprising: 
forwarding the copied data packet to a packet protocol determinator; and 

determining if the packet protocol of the copied data packet is ono likely to 
be infootod by th e d e t e cted oomputor - virus or comput e r worm -. 

6. (Currently Amended) A method as recited in claim 5, further 
comprising: 

receiving at a trash collector those copied data packets determined to be of a 
first set of one or more specific a protocols not lik e ly to bo infeotod by the 
det e ct e d computer viruo or computer worm ; and 

receiving and analyzing those copied data packets determined to be of a one 
or more specific protocol lik e ly to be infected by tho doteotod oomputor virus or 
computer worm at a filescan unit. 

7. (Currently Amended) A method as recited in claim 6, further 
comprising: 

determining by a virus/worm virus analyzer unit if those copied data packets 
received at the filescan unit are infected by the detected computer virus or 
computer worm; 

forwarding those packets determined not to be infected to the trash collector; 

analyzing the infected copied data packets; and 

generating a virus report based upon the analysis, 
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8. (Original) In a distributed network having a number of server computers and 
associated client devices, computer program product for isolating infected client devices from 
uninfected client devices, comprising: 

computer code for correlating network related virus infection information; 
determining if a virus outbreak has occurred based on the correlated information; 
computer code for isolating infected client devices from uninfected client devices when 
the virus outbreak is confirmed; 

computer code for monitoring all data packets in the network for the virus; 
computer code for identifying a packet type associated with the virus; 
computer code for blocking only the identified packet type; and 
computer readable medium for storing the code. 

9. (Canceled) 

10. (Currently Amended) Computer program product as recited in 
claim 9, further comprising: 

computer code for forwarding to a virus/worm virus analyzer unit coupled to 
the network computer virus/worm sensor only those data packets deemed to be 
infected by the identified computer virus or computer worm are. 

1 1 . (Currently Amended) Computer program product as recited in 
claim 10, wherein in the first mode, copying by the traffic controller 
substantially all data packets included in the network traffic; and 

computer code for forwarding the copied data packets to the virua/vvorm 
virus a nalvzer unit. 
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12. (Currently Amended) Computer program product as recited in 
claim 11, comprising: 

computer code for forwarding the copied data packet to a packet protocol 
determinator; and 

computer code for determining ♦# the packet protocol of the copied data 

i packet is one likely to b e infected by the dotooted computer viruo or comput e r 

I. 

worm , 

f 

I 13, (Currently Amended) Computer program product as recited in 

I claim 12, further comprising: 

] 

I computer code for receiving at a trash collector those copied data packets 

\ 

determined to be of «■ a first set of one or more specific protocols, not likely to bo 
I infootod by the dotooted oomputor virus or computer worm ; and 

I computer code for receiving and analyzing those copied data packets 

3 determined to be of a second set of one or more specific protocols likoly to bo 

inf e cted by th e detect e d computer virus or oomputor worm at a filescan unit. 

14, (Currently Amended) Computer program product as recited in 
claim 13, further comprising: 

computer code for determining by a virus/worm virus analyzer unit if those 
copied data packets received at the filescan unit are infected by the detected 
" computer virus or computer worm; 

computer code for forwarding those packets determined not to be infected to 
the trash collector; 
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computer code for analyzing the infected copied data packets; and 
computer code for generating a virus report based upon the analysis. 

i 
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